CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,816 vulnerabilities with CWE-502
CVE-2025-4905
MEDIUM
basestation3 < 3.0.4 - Deserialization of Untrusted Data in QC.py load_qc_pickl
CVSS 5.3
CVE-2025-48134
HIGH
WP Tabs <= 2.2.12 - PHP Object Injection via Untrusted Data Deserialization
CVSS 7.2
CVE-2025-4742
MEDIUM
XU-YIJIE grpo-flat <9024b43f091e2eb9bac65802b120c0b35f9ba856 - Dese...
CVSS 5.3
CVE-2025-4740
MEDIUM
BeamCtrl Airiana <11.0 - Deserialization
CVSS 5.3
CVE-2025-47784
CRITICAL
emlog < 2.5.14 - Deserialization of Untrusted Data via Crafted Nickname
CVSS 9.8
CVE-2025-4701
MEDIUM
VITA-MLLM Freeze-Omni <20250421 - Deserialization
CVSS 5.3
CVE-2025-47292
CRITICAL
Cap Collectif <commit 812f2a7d271b76deab1175bdaf2be0b8102dd198 - RCE
CVE-2025-3623
CRITICAL
Uncanny Automator < 6.4.0.2 - Unauthenticated PHP Object Injection via automator_api_decode_message()
CVSS 9.1
CVE-2025-30384
HIGH
Microsoft Office SharePoint - Code Injection
CVSS 7.4
CVE-2025-30382
HIGH
Microsoft Office SharePoint - Code Injection
CVSS 7.8
CVE-2025-30378
HIGH
Microsoft Office SharePoint - Code Injection
CVSS 7.0
CVE-2025-42999
CRITICAL
KEV
SAP NetWeaver Visual Composer Metadata Uploader - Code Injection
CVSS 9.1
CVE-2025-30012
CRITICAL
SAP Supplier Relationship Management - Unauthenticated Remote Code Execution via Live Auction Cockpit Deserialization
CVSS 10.0
CVE-2025-46738
MEDIUM
SEL-5033 acSELerator RTAC Software < 1.154.200.3500 - Remote Code Execution via Layout Data File Deserialization
CVSS 6.6
CVE-2025-47732
HIGH
Microsoft Dataverse - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.7
CVE-2025-47683
HIGH
WP Maintenance <6.1.9.7 - Code Injection
CVSS 7.2
CVE-2025-47629
HIGH
WP-CRM System <= 3.4.5 - PHP Object Injection via Untrusted Data Deserialization
CVSS 7.2
CVE-2025-0855
CRITICAL
PGS Core <= 5.8.0 - Unauthenticated PHP Object Injection via Import Header Deserialization
CVSS 9.8
CVE-2025-30165
HIGH
vLLM 0.5.2-0.10.0 - Remote Code Execution via Pickle Deserialization in ZeroMQ Communication
CVSS 8.0
CVE-2025-43852
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Model Path Deserialization
CVSS 9.8
CVE-2025-43851
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Model Deserialization
CVSS 9.8
CVE-2025-43850
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Torch Deserialization
CVSS 9.8
CVE-2025-43849
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Torch Deserialization
CVSS 9.8
CVE-2025-43848
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Torch Deserialization
CVSS 9.8
CVE-2025-43847
CRITICAL
Retrieval-based-Voice-Conversion-WebUI < 2.2.231006 - Remote Code Execution via Unsafe Torch Deserialization
CVSS 9.8
Details
Vulnerabilities
2,816
Exploit Likelihood
Medium